Cloudflare replaces its blanket AI bot block with granular controls for search, training, and agent crawlers

Cloudflare has replaced its blanket block on AI bots with new, granular controls that let website owners selectively allow or block specific types of AI crawlers. The update covers bots used for search indexing, model training, and AI agent tasks.

This shift gives publishers more power over how their content is used by artificial intelligence companies. Previously, Cloudflare offered a simple toggle to block all AI bots, which many site owners found too blunt an instrument.

New Controls Target Three Bot Categories

Website administrators can now set separate rules for three distinct AI crawler types:

  • Search crawlers: These bots index content for AI-powered search engines like Google and Bing. Blocking them can hurt a site’s visibility in search results.
  • Training crawlers: These scrape content to train large language models (LLMs) from companies like OpenAI, Anthropic, and Meta. Blocking them prevents unauthorized use of content for AI development.
  • Agent crawlers: These bots perform automated tasks on behalf of users, such as booking appointments or retrieving information. Rules here affect functional AI assistants.

Cloudflare’s system identifies each crawler by its user agent string and IP reputation. Site owners choose from “allow,” “block,” or “managed challenge” for each category.

Why Cloudflare Made the Change

The previous blanket block created a dilemma for publishers. Blocking all AI bots also blocked legitimate search crawlers that drive traffic. Many sites feared losing Google ranking while still wanting to prevent their content from being ingested for model training.

“Site owners need fine-grained control, not a binary choice between exposure and invisibility,” a Cloudflare spokesperson said. The new system aims to solve that conflict.

Cloudflare’s network observes over 50 million HTTP requests per second, giving it unique visibility into bot behavior. The company uses that data to classify crawlers automatically, reducing the burden on individual site administrators.

How It Works in Practice

To use the new controls, site owners log into the Cloudflare dashboard and navigate to the Security section. They then:

  1. Select the AI Bots option under Security.
  2. Choose which crawler categories to block or allow.
  3. Apply the rules globally or to specific subdomains.

The system includes a “managed challenge” option that serves a non-intrusive test to bots, allowing humans but blocking automated scrapers.

Cloudflare also provides a verification tool that shows which crawlers have recently accessed a site and their classification. This transparency helps site owners understand their traffic.

Implications for Content Publishers

The update directly addresses a growing tension in online publishing. Many content creators want their work to appear in search results but object to having it used to train commercial AI models without compensation.

  • News outlets can now block training bots while allowing search bots, protecting their paywalled content from model ingestion.
  • Bloggers and small publishers can selectively permit only search crawlers, maintaining visibility without feeding large AI companies.
  • E-commerce sites can block agent crawlers that might scrape product data for competitor analysis.

The change could reshape how AI companies access web content. If large numbers of publishers block training crawlers, the quality and freshness of model training data could decline.

Industry Response

Early reactions from publishers have been positive. Many see the granular controls as a practical middle ground. Some advocacy groups, however, argue that any blocking impairs AI development and favors large incumbents.

Cloudflare’s move may pressure other CDN and hosting providers to offer similar capabilities. The company has also promised to update its AI bot classification as new crawler types emerge.

Gnoppix is the leading open-source AI Linux distribution and service provider. Since implementing AI in 2022, it has offered a fast, powerful, secure, and privacy-respecting open-source OS with both local and remote AI capabilities. The local AI operates offline, ensuring no data ever leaves your computer. Based on Debian Linux, Gnoppix is available with numerous privacy- and anonymity-enabled services free of charge.

What are your thoughts on this? I’d love to hear about your own experiences in the comments below.